I'm trying to get the ACL setting correct so some admins can only edit some specific pages I selected in a resource group. I followed a few tutorials but I don't get the result the tutorials say. Thus I want to know if I do the right thing.
- Created user "Test"
- Created usergroup "Editors"
- Added role: "Editor" with authority level: 10
- Added user "Test" to usergroup "Editors" as "Editor"
- Created resource group "Editable Documents"
- Added a resource to resource group "Editable Documents"
- Added policy "Content Editor" with the following rights:
change_profile, class_map, countries, edit_document, frames, help, home, load, logout, resource_tree, save_document, view, view_document, new_document
Usergroup context settings
mgr Editor Content Editor
web Editor Load, List and View
Usergroup resourcegroup settings
Editable Documents Editor Edit resource mgr
What I expected is that I could only edit the document in the resourcegroup and not the others. But I can't edit any document.
I did a flush permissions and logged out and in.
Try changing the Resource Group Access ACL entry policy to Resource and see if that fixes it. If so, there is some necessary permission missing from the Content Editor policy. List, for one.
Forgot to mention that, "Edit resource" is duplicate of "Resource" with all permissions.
If you can't edit any documents at all, the problem is most likely with the *Context* Access ACL entry for that user group.
Alright, I'm starting to understand the ACL a little bit more. The problem is that if a resource is not in any documentgroup and/or that documentgroup is not assigned to the administrator group that resources can be edited by any group with edit rights.
Currently my solution is to create a document group with all the resources and assign this to the administrator group. When I now create a new document group with only the resources that certain user may edit I can assign this to the user. And they can only view and edit these resources.
Is this the correct solution or are there better ways?
That's exactly right. You can automatically add new resources to the protected group with the DefaultResourceGroup extra.
You can also add new users to a default user group with the DefaultUserGroup extra.